Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

CrowdStrike Integration with Juniper Mist Access Assurance

Follow these steps to understand the CrowdStrike Falcon EDR integration. Learn how to authorize the CrowdStrike API with your Juniper Mist organization, configure EDR-based policy rules, map endpoint security attributes to network access policies, and monitor CrowdStrike detection and endpoint events directly from Mist.

Juniper Mist Access Assurance supports native integration with CrowdStrike Falcon EDR, enabling evaluation of endpoint security posture across devices. CrowdStrike Falcon EDR provides endpoint threat detection data with severity levels ranging from Informational to Critical. Juniper Mist Access Assurance evaluates the current threat severity and uses this information in authentication policies to enforce appropriate network access decisions.

Threat Severity Retrieval from CrowdStrike

Juniper Mist Access Assurance integrates with CrowdStrike Falcon EDR using webhooks to receive real-time detection events. Whenever a detection is created, updated, or closed in CrowdStrike, a notification is sent to Juniper Mist Access Assurance.

CrowdStrike Falcon EDR assigns each detection a severity level of Informational, Low, Medium, High, or Critical. Juniper Mist Access Assurance evaluates all currently open detections for an endpoint and determines the effective threat severity based on the highest severity using the following priority: Critical > High > Medium > Low > Informational.

For example:

  • If an endpoint already has an open Low-severity detection and a new High-severity detection is reported, the effective severity is updated to High.

  • If an Informational detection is reported while a Low-severity detection remains open, the effective severity remains Low.

If an endpoint has no open detections, Juniper Mist Access Assurance classifies the endpoint as Healthy. Healthy is a Juniper Mist Access Assurance posture state and does not correspond to a CrowdStrike severity level.

When a detection's severity changes or an open detection is resolved, Juniper Mist Access Assurance automatically triggers a Change of Authorization (CoA), when required, to re-evaluate the endpoint and apply the appropriate network access policy. This enables dynamic network access enforcement based on the endpoint’s current CrowdStrike threat status.

Note: The CoA functionality is supported only on APs running firmware version 0.14 or later.

Figure 1 illustrates how Juniper Mist Access Assurance retrieves CrowdStrike-managed device severity status for authentication.

Figure 1: Threat Severity Retrieval from CrowdStrike Threat Severity Retrieval from CrowdStrike

Juniper Mist Access Assurance uses the following information during client authentication to match a client with an endpoint record in CrowdStrike Falcon EDR:

  • Device certificate CN (Hostname)—For EAP-TLS authentication, Juniper Mist Access Assurance matches the certificate CN with the endpoint hostname reported by CrowdStrike Falcon. This hostname-based lookup supports both randomized and non-randomized MAC addresses.

  • MAC Address Fallback—If the endpoint cannot be matched using the certificate CN or hostname, Juniper Mist Access Assurance falls back to the client MAC address to locate the corresponding endpoint record in CrowdStrike Falcon. In this case, the client's current MAC address must be synchronized with the CrowdStrike endpoint record, regardless of whether the device is using a randomized or its original MAC address.

Configure Client ID and Secret in CrowdStrike Console

To integrate CrowdStrike with Juniper Mist, you'll need to set up a client ID.
  1. Log in to the CrowdStrike Falcon Console and navigate to Support and Resources >Resources and Tools>API Clients and Keys.
  2. Click Create API Client.
  3. Provide the API Client Name, and then assign the following API permissions:
    • Alerts—Read

    • Detections—Read

    • Hosts—Read

    • NGSIEM—Read and Write

      NGSIEM requires both Read and Write permissions. Although the integration only retrieves data, CrowdStrike's Humio query APIs create a temporary server-side query job before returning results. As the creation of the query is classified as a write operation, the Write permission is required in addition to the Read permission.

  4. Click Create.

    Once the API client is created successfully, the Client ID and Client Secret are displayed.

  5. Copy and securely store these credentials. These credentials are required to configure the integration between CrowdStrike EDR and Juniper Mist Access Assurance.

Link a CrowdStrike Account to a Mist Organization

To link a CrowdStrike account to an organization:
  1. Log in to the Mist organization using an account with Super User privileges. Navigate to Organization>Access>Identity>Linked Accounts, and select CrowdStrike.
  2. Enter the following details:
    • Customer ID (CID)—Available in the CrowdStrike Falcon Console under Host Setup and Management>Sensor Downloads.

    • Client ID and Client Secret—Generated during the creation of the CrowdStrike API client in Configure Client ID and Secret in CrowdStrike Console.

    • Click Link Account.

      After the account is successfully linked, the Last Status field (which indicates the integration status) will display Success. A Webhook URL and Webhook Secret will also be generated. These values are required to configure event notifications from CrowdStrike to Juniper Mist Access Assurance.

Configure Webhooks in CrowdStrike Falcon

To configure webhooks in CrowdStrike Falcon:
  1. In the CrowdStrike Falcon console, navigate to CrowdStrike Store>All apps.
  2. Search for CrowdStrike Webhook and select the application.
  3. Click Configure, and then select Add Configuration.
  4. Provide a name for the webhook configuration.
  5. Enter the Webhook URL and Secret Key generated during the CrowdStrike account linking process with your Mist organization. See Link a CrowdStrike Account to a Mist Organization.
  6. Click Save Configuration to create the webhook.

Configure Webhook Workflows

You need to configure two webhook workflows in CrowdStrike to notify Juniper Mist Access Assurance about severity events, which are threat detections with an assigned severity level. These workflows ensure that Juniper Mist Access Assurance is updated whenever a severity event is created, updated, or closed.

Configure a Webhook Workflow for Endpoint Severity Detections in CrowdStrike

By configuring a workflow for endpoint severity detections, you can enable forwarding of details for newly identified detections to Juniper Mist Access Assurance.
  1. In the CrowdStrike Falcon Console, navigate to Fusion SOAR>Workflows and click Create Workflow.
  2. Select Create Workflow from Scratch and click Next.
  3. Under Trigger, search for detection and select Detection>EPP Detection, then click Next.
  4. Click the Action icon to add a workflow action. Search for Call Webhook, and select it from the results.
  5. Configure the webhook action with the following details:
  6. Click Next.
  7. Provide a name for the workflow and click Publish.
  8. Ensure that the workflow Status is set to Enabled, and click Publish Workflow.

Configure a Webhook Workflow for Audit Event Detections in CrowdStrike

To keep Juniper Mist Access Assurance synchronized with threat detection status updates, configure an audit event detection webhook workflow. This workflow enables CrowdStrike to forward detection status change events to Juniper Mist Access Assurance, including transitions from open to closed and from closed to reopened.

  1. In the CrowdStrike Falcon Console, navigate to Fusion SOAR>Workflows and click Create Workflow.
  2. Select Create Workflow from Scratch and click Next.
  3. Under Trigger, search for and select Audit Event > Detection, then click Next.
  4. Set Type to Status, and then click Next.
  5. Click the Action icon to add a workflow action. Search for Call Webhook, and select it from the results.
  6. Configure the webhook action with the following details:
    • Webhook Name—Select the webhook configuration that you created in Configure Webhooks in CrowdStrike Falcon

    • Data Format—Default

    • Data to Include—Detection ID, Detection severity, Detection status, Host ID, Target status, and Target status (Display Name)

  7. Click Next.
  8. Provide a name for the workflow and click Publish.
  9. Ensure that the workflow Status is set to Enabled, and click Publish Workflow.

Juniper Mist Access Assurance Endpoint Severity Evaluation

Juniper Mist Access Assurance determines an endpoint's severity state based on detection information retrieved from CrowdStrike. CrowdStrike classifies detections using the following severity levels:

  • Informational

  • Low

  • Medium

  • High

  • Critical

When an endpoint is onboarded, its initial severity state is set to Unknown. After initial authentication, Juniper Mist Access Assurance queries CrowdStrike to retrieve the endpoint's detection information.

If no open detections are found within the last 2 hours, the endpoint is classified as Healthy.

Note: Healthy is a Juniper Mist Access Assurance posture state and does not correspond to a CrowdStrike severity level.

If an open detection is found, the corresponding CrowdStrike severity is assigned to the endpoint. When multiple open detections exist, the highest severity determines the effective endpoint severity, using the following precedence order:

Critical > High > Medium > Low > Informational

For example, if an endpoint has both a Medium and a High open detection, the endpoint severity is reported as High.

Configure Auth Policy Labels and Rules for CrowdStrike Severity States

Configure Auth Policy Labels to classify endpoints based on their CrowdStrike severity state, and use these labels to define the corresponding auth policies.
  1. Navigate to Organization>Access>Auth Policy Labels and click Add Label.

    You can configure a label with a single severity value or multiple severity values. Supported values are Critical, High, Medium, Low, Informational, Healthy, and Unknown.

  2. Navigate to Organization>Access>Auth Policies and configure authentication rules using the configured Auth Policy Labels. These rules determine which access policy is applied to endpoints based on their current severity classification.
  3. Create an authentication rule to allow the initial device connection. The initial EDR lookup for a new client occurs after the device has been authenticated for the first time. CS INITIAL ALLOW is the auth rule in the following example.
    Note: Do not include the EDR Severity labels in the match conditions for this rule. You can optionally use the Unknown Severity as a match criterion. Ensure that this rule is placed at a lower priority than the standard access policies.
  4. (Optional) Configure the CoA action to be taken when the endpoint’s CrowdStrike severity changes and updated policies need to be applied. Navigate to Organization>Settings>Access Assurance>MDM and EDR CoA Action. Select one of the following actions: CoA Reauthenticate (Default) or CoA Disconnect.

Client Connection and Verification

When a client is onboarded for the first time, Juniper Mist Access Assurance performs an EDR lookup after the client is authenticated. If no open detections are found within the past 2 hours, Juniper Mist Access Assurance assigns the client a CrowdStrike Healthy posture.

When a new detection is triggered (for example, Medium), CrowdStrike sends a webhook notification to Juniper Mist Access Assurance. Access Assurance then sends a CoA to the client and applies the updated access policy.

When the detection is closed, Juniper Mist Access Assurance receives the updated status, triggers another CoA, and applies the corresponding updated access policy.